Stored Cross-Site Scripting Vulnerability in ProfilePress Plugin for WordPress
CVE-2024-1535
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1535?
The ProfilePress plugin for WordPress contains a stored cross-site scripting vulnerability that arises from inadequate input sanitization and output escaping of user-supplied attributes in its shortcodes. This flaw allows authenticated attackers with contributor-level or higher permissions to inject malicious scripts that will execute when other users access the affected pages. All versions up to and including 4.15.2 are impacted, making it crucial for site administrators to address this security risk to protect their users from potential exploits.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress * <= 4.15.2